Threadlinqs IntelligenceStart free

Daily debrief · Tuesday2026-07-28

Daily Intelligence Briefing — Tuesday, July 28, 2026

11 critical10 high3 medium

On 2026-07-28, Threadlinqs published 18 new threat reports and updated 7, 11 rated critical and 10 high, spanning 235 MITRE ATT&CK techniques and 10 named threat actors. Coverage that day added 225 new detection rules and 821 extracted indicators.

New threats
187 updated
Critical / high
2111 critical · 10 high
ATT&CK techniques
235Observed in the day’s reports
Threat actors
10Named in the reports
Indicators
821Count only · values are Red+
Detection rules
225New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Netskope "Beyond Shadow AI" Report: Shadow AI Data Exposure Escalates as Agentic AI/MCP Governance Lags Enterprise Adoption. Real-Time Credential Relay Phishing Campaign Targets Call of Duty Mobile Players via Fake CP Giveaway. AutoIT Payload Injector Delivers VIPKeylogger via Phishing/RAR Chain into charmap.exe.

Highlights

  • TL-2026-1734 — Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent Offenders
  • TL-2026-1737 — Wrench Attacks: Physical Coercion Bypasses Cryptocurrency Wallet Encryption Amid 33% YoY Surge in H1 2026
  • TL-2026-1738 — Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience
  • TL-2026-1741 — Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and BridgeHead/ArcBridge WebSocket Tunnelers Against Middle East and Africa
  • TL-2026-1742 — LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installed

Theme of the day

  • privilege-escalation
  • lateral-movement
  • credential-theft
  • remote-code-execution
  • credential-harvesting

Threats published

25 threat lines in the 2026-07-28 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

235 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

10 named threat actors across the reports.

Nation-state attribution

  • Israel
  • Iran
  • North Korea (DPRK)
  • Nigeria
  • China

Threat categories

  • THREAT_INTEL
  • PHISHING
  • MALWARE
  • APT
  • VULNERABILITY
  • SUPPLY_CHAIN
  • DATA_BREACH

Severity breakdown

  • critical11
  • high10
  • medium3
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

821 indicators of compromise · Red and above. Compare plans
  • behavioral 232
  • entity 133
  • network 117
  • file 87
  • tool 74
  • infrastructure 68
  • package 52
  • malware 41
  • technique 15
  • vulnerability 2
225 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans